Connect with me!

Have a question? Want to hire me? Reach out and Connect!
I'm available for remote and onsite consulting!
To live chat with me, Click Here!
Categories: Astaro

Astaro Security Gateway 8.2 – E-Mails being rejected due to RDNS

Recently I upgraded a bunch of ASG’s to version 8.2. While most of the upgrades went smoothly, I did have an issue with a specific box at one of my clients offices.

We had some reports that incomming e-mails were being rejected. After checking the Mail Manager, these e-mails were being rejected due to numerous RDNS failures. While most of the incomming message sources actually didn’t have a properly configured RDNS, I finally noticed in one case that a specific sender actually did have properly configured Reverse DNS…

Googling this specific issue came up with nothing, however I noticed in the DNS proxy on the ASG box, that since the upgrade numerous errors were going through on a daily basis:

mail named: Last message ‘unexpected RCODE (RE’ repeated 2 times, supressed by syslog-ng on host.name

mail named[5466]: lame server resolving ‘X’

These errors were filling the log. I went ahead and logged into WebAdmin and removed the DNS forwarders, hit apply, flushed DNS cache, then re-inserted the DNS forwarders. This resolved the issue.

Stephen Wagner

Stephen Wagner is President of Digitally Accurate Inc., an IT Consulting, IT Services and IT Solutions company. Stephen Wagner is also a VMware vExpert, NVIDIA NGCA Advisor, and HPE Influencer, and also specializes in a number of technologies including Virtualization and VDI.

View Comments

  • Update on this... Turns out it doesn't fix the issue. On numerous ASG's I've actually had to disable RDNS checking due to issues with incoming e-mails. I have a ticket open with Astaro. I'll post an update as news comes in...

  • You will find that the issue is related to forward DNS, Astaro checks both reverse and forward DNS. We have the same issues since 8.2 was released and after some checking came up with this info. So Astaro is not at fault (however it annoys me how many mail servers don't have rDNS setup).

  • Thanks Dan,

    So it all makes sense now... ASG 8.2 checks both forward and reverse and wants them to match each other? If not it reports it as failed?

    Stephen

Share
Published by

Recent Posts

How to properly decommission a VMware ESXi Host

While most of us frequently deploy new ESXi hosts, a question and task not oftenly discussed is how to properly decommission a VMware ESXi host. Some might be surprised to… Read More

4 months ago

Disable the VMware Horizon Session Bar

This guide will outline the instructions to Disable the VMware Horizon Session Bar. These instructions can be used to disable the Horizon Session Bar (also known as the Horizon Client… Read More

4 months ago

vGPU Enabled VM DRS Evacuation during Maintenance Mode

Normally, any VMs that are NVIDIA vGPU enabled have to be manually migrated with manual vMotion if a host is placed in to maintenance mode, to evacuate the host. While… Read More

4 months ago

GPU issues with the VMware Horizon Indirect Display Driver

You may experience GPU issues with the VMware Horizon Indirect Display Driver in your environment when using 3rd party applications which incorrectly utilize the incorrect display adapter. This results with… Read More

4 months ago

Synology DS923+ VMware vSphere Use case and Configuration

Today we're going to cover a powerful little NAS being used with VMware; the Synology DS923+ VMware vSphere Use case and Configuration. This little (but powerful) NAS is perfect for… Read More

4 months ago

How to Install the vSphere vCenter Root Certificate

Today we'll go over how to install the vSphere vCenter Root Certificate on your client system. Certificates are designed to verify the identity of the systems, software, and/or resources we… Read More

5 months ago
Powered and Hosted by Digitally Accurate Inc. - Calgary IT Services, Solutions, and Managed Services